Vulnerability Description
A command injection issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker can exploit this to elevate privileges from a user with BMC administrative privileges.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Supermicro | X11Ssm-F Firmware | 1.66 |
| Supermicro | X11Ssm-F | - |
| Supermicro | X11Sae-F Firmware | 1.66 |
| Supermicro | X11Sae-F | - |
| Supermicro | X11Sse-F Firmware | 1.66 |
| Supermicro | X11Sse-F | - |
Related Weaknesses (CWE)
References
- https://www.supermicro.com/en/support/security_BMC_IPMI_Oct_2023Vendor Advisory
- https://www.supermicro.com/en/support/security_center#%21advisoriesVendor Advisory
- https://www.supermicro.com/en/support/security_BMC_IPMI_Oct_2023Vendor Advisory
- https://www.supermicro.com/en/support/security_center#%21advisoriesVendor Advisory
FAQ
What is CVE-2023-40289?
CVE-2023-40289 is a vulnerability with a CVSS score of 7.2 (HIGH). A command injection issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker can exploit this to elevate privileges from a user with BMC administrative privileges.
How severe is CVE-2023-40289?
CVE-2023-40289 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-40289?
Check the references section above for vendor advisories and patch information. Affected products include: Supermicro X11Ssm-F Firmware, Supermicro X11Ssm-F, Supermicro X11Sae-F Firmware, Supermicro X11Sae-F, Supermicro X11Sse-F Firmware.